Can I market to customers who provide their email addresses?

When a customer places an order with our store the API gives us their email address. Under GDPR can I add this to our marketing lists? Is there a way to have people opt-in on this process or would Legitimate Interest be acceptable here?